How to Answer Penetration Testing Questions

Your customer asked: “Do you perform penetration testing?”

The short answer

Answer “yes” only when your company has actually had the relevant systems or application tested through a penetration-testing engagement. Vulnerability scans, automated security checks, and a written policy are not automatically penetration tests.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

A reviewer is usually looking for deliberate testing in which security weaknesses are actively investigated or exploited within an authorized scope. They may ask who performed the test, when it occurred, what was in scope, and whether significant findings were addressed.

How to answer accurately

Start with the version that matches reality.

1

If a penetration test was completed

Describe the scope, timing, and whether it was internal or independent only to the level your company is comfortable and authorized to share. Reference an executive summary or attestation if available rather than exposing sensitive details unnecessarily.

2

If you only run vulnerability scans

Say that penetration testing is not currently performed, then describe vulnerability scanning separately if the questionnaire allows context.

3

If you are unsure what a vendor performed

Review the engagement statement, report, or service description before labeling the activity a penetration test.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Penetration-test executive summary
  • Attestation or completion letter
  • Statement of work defining the test scope
  • Remediation record for findings

What not to say

  • That vulnerability scanning is penetration testing.
  • That testing occurs annually unless the cadence is established and supported.
  • That a report proves every system or product was in scope.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

This is a classic Oredra distinction: a claimed test, available evidence, test scope, and independent performance should remain explicit instead of collapsing into one “yes.”

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions